Junglewise Threat Intelligence

CVE-2026-7402: MeWare PDKS flooding vulnerability due to improper rate limiting

CVE-2026-7402 · Severity: high · CVSS 8.1 · Published 2026-04-30

Executive brief

MeWare PDKS, a personnel attendance control system used to track employee hours and building access, is vulnerable to a flooding attack. An attacker can overwhelm the system with requests, potentially causing service outages or disrupting the integrity of attendance records. This could lead to operational delays and inaccurate payroll or security logging.

Technical details

A vulnerability classified as CWE-799 (Improper Control of Interaction Frequency) exists in MeWare PDKS. The system fails to adequately limit the rate or frequency of incoming requests, allowing an authenticated user to perform a 'flooding' attack. This network-based attack can be executed with low complexity and requires only basic user privileges. Successful exploitation can lead to a denial-of-service condition or high impact on the integrity of the system's data. The issue is addressed in version VMYR_3.5.2025117.

Affected products

  • MeWare Software Development Inc. PDKS from V16.20200313 before VMYR_3.5.2025117

Timeline

  • 2026-04-30: disclosed
  • 2026-04-30: advisory

References

Related threats